{"info":{"_postman_id":"72f39247-d154-4dfd-ab6c-817ca036f778","name":"VettiGuard API v1","description":"Generated from the same route catalogue as the VettiGuard OpenAPI contract. New integrations should keep base_url set to the canonical API subdomain.","schema":"https://schema.getpostman.com/json/collection/v2.1.0/collection.json","_exporter_id":"vettiguard-contract-generator"},"variable":[{"key":"base_url","value":"https://api.vettiguard.com/v1","type":"string"},{"key":"site_key","value":"vg_site_replace_me","type":"string"},{"key":"site_secret","value":"vg_secret_replace_me","type":"secret"},{"key":"mobile_credential","value":"vg_credential_replace_me","type":"secret"},{"key":"stripe_signature","value":"generated-by-stripe","type":"secret"},{"key":"agent_id","value":"replace-with-registered-agent-uuid","type":"string"},{"key":"agent_timestamp","value":"replace-with-current-unix-timestamp","type":"string"},{"key":"agent_nonce","value":"replace-with-random-single-use-nonce","type":"string"},{"key":"agent_signature","value":"generated-hmac-sha256","type":"secret"}],"item":[{"name":"API Protection","item":[{"name":"Assess API abuse and resource-exhaustion risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/api-protection/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"method\": \"POST\",\n    \"path\": \"/api/orders\",\n    \"action\": \"order-create\",\n    \"authentication_present\": true,\n    \"content_type\": \"application/json\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"request_id\": \"request-uuid\",\n    \"idempotency_key\": \"order-create-9942\",\n    \"payload_fingerprint\": \"sha256-canonical-payload\",\n    \"body_bytes\": 2048,\n    \"page_size\": 0,\n    \"query_depth\": 2,\n    \"resource_cost\": 25\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate an API Protection assessment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/api-protection/feedback","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"label\": \"legitimate\",\n    \"reason_code\": \"customer-confirmed\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Account Defence","item":[{"name":"Assess an account-sensitive event","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/account/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-session-device\",\n    \"event_type\": \"login\",\n    \"outcome\": \"failure\",\n    \"account_age_days\": 420,\n    \"compromised_password\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate an account-risk assessment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/account/feedback","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"label\": \"credential_stuffing\",\n    \"reason_code\": \"customer-confirmed\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Retrieve breached-password hash suffixes","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/account/password/range","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"prefix\": \"5BAA6\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Trust or revoke an account device","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/account/trusted-device","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"trust\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-session-device\",\n    \"label\": \"Customer laptop\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Agent Trust","item":[{"name":"Read a signed agent approval status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"X-VettiGuard-Agent","value":"{{agent_id}}","type":"text"},{"key":"X-VettiGuard-Timestamp","value":"{{agent_timestamp}}","type":"text"},{"key":"X-VettiGuard-Nonce","value":"{{agent_nonce}}","type":"text"},{"key":"X-VettiGuard-Signature","value":"{{agent_signature}}","type":"text"}],"url":"{{base_url}}/agents/approval/status","description":"Signed agent request using HMAC-SHA256 over timestamp, nonce, and the exact raw JSON body. Agent secrets must remain in a trusted server-side secret manager.","body":{"mode":"raw","raw":"{\n    \"approval_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Evaluate a signed agent operation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"X-VettiGuard-Agent","value":"{{agent_id}}","type":"text"},{"key":"X-VettiGuard-Timestamp","value":"{{agent_timestamp}}","type":"text"},{"key":"X-VettiGuard-Nonce","value":"{{agent_nonce}}","type":"text"},{"key":"X-VettiGuard-Signature","value":"{{agent_signature}}","type":"text"}],"url":"{{base_url}}/agents/decision","description":"Signed agent request using HMAC-SHA256 over timestamp, nonce, and the exact raw JSON body. Agent secrets must remain in a trusted server-side secret manager.","body":{"mode":"raw","raw":"{\n    \"request_id\": \"agent-request-991\",\n    \"action\": \"order-status\",\n    \"scope\": \"orders.read\",\n    \"resource_id\": \"ORDER-9942\",\n    \"subject_id\": \"customer-1842\",\n    \"summary\": \"Read an order status for an authenticated customer.\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Billing webhooks","item":[{"name":"Receive signed Stripe billing events","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Stripe-Signature","value":"{{stripe_signature}}","type":"text"}],"url":"{{base_url}}/billing/stripe/webhook","description":"Provider-to-provider callback. The signature must be verified before the event changes application state.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Concurrency Control","item":[{"name":"Acquire an expiring workload concurrency lease","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/concurrency/acquire","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"report.generate\",\n    \"method\": \"POST\",\n    \"subject_id\": \"customer-1842\",\n    \"route\": \"/api/reports\",\n    \"lease_ttl_seconds\": 120,\n    \"idempotency_key\": \"report-request-9942\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Release a workload concurrency lease","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/concurrency/release","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"lease_token\": \"vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Renew an active workload concurrency lease","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/concurrency/renew","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"lease_token\": \"vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature\",\n    \"lease_ttl_seconds\": 120\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Dependency Resilience","item":[{"name":"Admit a downstream dependency call","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/dependency-resilience/admit","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"dependency_key\": \"payments-provider\",\n    \"action\": \"payment.capture\",\n    \"method\": \"POST\",\n    \"subject_id\": \"customer-1842\",\n    \"route\": \"/api/payments\",\n    \"is_retry\": false,\n    \"admission_ttl_seconds\": 45\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Report an admitted dependency outcome","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/dependency-resilience/feedback","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"admission_token\": \"vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature\",\n    \"outcome\": \"success\",\n    \"latency_ms\": 240\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Detection intelligence","item":[{"name":"Annotate a detection assessment outcome","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/detection/feedback","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"assessment_id\": \"4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24\",\n    \"label\": \"abuse\",\n    \"reason_code\": \"confirmed-credential-stuffing\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Developer sandbox","item":[{"name":"Issue a non-production sandbox response token","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/sandbox/issue","description":"Public metadata endpoint that does not reveal private infrastructure details.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_test_site_key\",\n    \"scenario\": \"success\",\n    \"action\": \"checkout\",\n    \"hostname\": \"sandbox.example.test\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"List deterministic sandbox verification scenarios","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/sandbox/scenarios","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Verify a deterministic sandbox response token","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/sandbox/siteverify","description":"Public metadata endpoint that does not reveal private infrastructure details.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_test_secret_demo_only\",\n    \"response\": \"vgsbx.generated-token\",\n    \"action\": \"checkout\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Device intelligence","item":[{"name":"Assess server-derived device assurance and risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/device/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"platform\": \"web\",\n    \"new_device\": false,\n    \"device_integrity_score\": 0.92000000000000003996802888650563545525074005126953125\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Digital Credentials","item":[{"name":"Issue a holder-bound selective-disclosure identity credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/credentials/issue","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"holder_token\": \"vgid_replace_me\",\n    \"holder_jwk\": {\n        \"kty\": \"EC\",\n        \"crv\": \"P-256\",\n        \"x\": \"base64url-x\",\n        \"y\": \"base64url-y\"\n    },\n    \"claims\": [\n        \"identity_verified\",\n        \"assurance_level\",\n        \"age_over_18\"\n    ],\n    \"valid_days\": 180\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read VettiGuard digital credential issuer metadata","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/credentials/issuer","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Read credential issuer public signing keys","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/credentials/jwks","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Select disclosures and prepare a holder-bound presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/credentials/present","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"credential\": \"issuer-jwt~disclosure~\",\n    \"claims\": [\n        \"identity_verified\",\n        \"age_over_18\"\n    ],\n    \"audience\": \"https://app.example.com\",\n    \"nonce\": \"challenge-nonce\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create a nonce-bound credential presentation challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/credentials/presentation/challenge","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"audience\": \"https://app.example.com\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a VettiGuard digital credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/credentials/revoke","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"credential_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"holder_token\": \"vgid_replace_me\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read a signed Token Status List","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/credentials/status-list","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Read Verified Identity credential type metadata","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/credentials/types/verified-identity-v1","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Verify selective disclosures and holder key binding","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/credentials/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"presentation\": \"issuer-jwt~disclosure~kb-jwt\",\n    \"challenge_token\": \"opaque-challenge-token\",\n    \"audience\": \"https://app.example.com\",\n    \"nonce\": \"challenge-nonce\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Edge Enforcement","item":[{"name":"Post edge decision","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/edge/decision","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"method\": \"POST\",\n    \"path\": \"/checkout/confirm\",\n    \"hostname\": \"shop.example.com\",\n    \"action\": \"checkout-confirm\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"fraud_assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post edge preclearance issue","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/edge/preclearance/issue","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"decision_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"verification_succeeded\": true,\n    \"hostname\": \"shop.example.com\",\n    \"action\": \"checkout-confirm\",\n    \"path_prefix\": \"/checkout\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post edge preclearance verify","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/edge/preclearance/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"token\": \"vgec.payload.signature\",\n    \"hostname\": \"shop.example.com\",\n    \"path\": \"/checkout/confirm\",\n    \"action\": \"checkout-confirm\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Facial authorization","item":[{"name":"Complete facial authorization capture","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/authorization/complete","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"intent_token\": \"vg_authorization_intent_replace_me\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create an operation-bound facial authorization intent","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/authorization/intent","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"approve-transfer\",\n    \"operation_reference\": \"TRANSFER-12345\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a facial authorization capture session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/authorization/session","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"intent_token\": \"vg_authorization_intent_replace_me\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify an operation-bound facial authorization proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/authorization/siteverify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"intent_token\": \"vg_authorization_intent_replace_me\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Facial enrollment","item":[{"name":"Complete facial enrollment capture","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/enrollment/complete","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"intent_token\": \"vg_enrollment_intent_replace_me\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create a facial enrollment intent","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/enrollment/intent","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"identity-enrollment\",\n    \"consent_version\": \"2026-08\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a facial enrollment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/enrollment/revoke","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-4821\",\n    \"reason\": \"customer-request\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a facial enrollment capture session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/enrollment/session","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"intent_token\": \"vg_enrollment_intent_replace_me\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a facial enrollment proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/enrollment/siteverify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"intent_token\": \"vg_enrollment_intent_replace_me\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read facial enrollment status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/enrollment/status","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-4821\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Facial liveness","item":[{"name":"Complete a browser facial-liveness session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/complete","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"session_token\": \"vg_facial_session_replace_me\",\n    \"capture\": {\n        \"frames\": [\n            \"base64-jpeg-frame\"\n        ]\n    }\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Select a browser facial verification level","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/decision","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"risk_level\": \"high\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a browser facial-liveness session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/session","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"action\": \"account-recovery\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Cancel a browser facial session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/session/cancel","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"session_token\": \"vg_facial_session_replace_me\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read browser facial session status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/session/status","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"session_token\": \"vg_facial_session_replace_me\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a facial-liveness proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/facial/siteverify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"response\": \"vg_facial_response_replace_me\",\n    \"action\": \"account-recovery\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Fraud Defence","item":[{"name":"Assess email quality and disposable-address risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/fraud/email/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"email\": \"customer@example.com\",\n    \"device_id\": \"browser-device\",\n    \"event_type\": \"signup\",\n    \"outcome\": \"attempt\",\n    \"email_verified\": false,\n    \"disposable_email\": false,\n    \"domain_age_days\": 3200\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate a fraud-risk assessment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/fraud/feedback","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"label\": \"payment_fraud\",\n    \"reason_code\": \"customer-confirmed\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Assess SMS pumping and OTP abuse risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/fraud/sms/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"phone\": \"+2348000000000\",\n    \"device_id\": \"browser-device\",\n    \"event_type\": \"otp_request\",\n    \"outcome\": \"attempt\",\n    \"phone_verified\": false,\n    \"high_cost_destination\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Assess transaction and commerce fraud risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/fraud/transaction/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"transaction_id\": \"ORDER-9942\",\n    \"device_id\": \"browser-device\",\n    \"event_type\": \"payment\",\n    \"outcome\": \"attempt\",\n    \"amount\": 125000,\n    \"currency\": \"NGN\",\n    \"high_value\": true,\n    \"new_payee\": true,\n    \"email_verified\": true,\n    \"phone_verified\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Human verification","item":[{"name":"Retrieve a public branding logo","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/branding/{profile_id}/logo","description":"Returns a normalized PNG logo for the UUID branding profile referenced by a challenge response. The asset contains presentation data only and is safe for cross-origin image rendering."},"response":[]},{"name":"Issue a browser verification challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/challenge","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"action\": \"contact-form\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a browser response token","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/siteverify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"response\": \"single-use-response-token\",\n    \"remoteip\": \"203.0.113.10\",\n    \"action\": \"contact-form\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Solve a browser verification challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/solve","description":"Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.","body":{"mode":"raw","raw":"{\n    \"site_key\": \"vg_site_replace_me\",\n    \"challenge_id\": \"4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24\",\n    \"answer\": true,\n    \"action\": \"contact-form\",\n    \"telemetry\": {\n        \"elapsed_ms\": 2450\n    }\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile API Protection","item":[{"name":"Assess native API abuse and resource risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/api-protection/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"method\": \"GET\",\n    \"path\": \"/api/catalog\",\n    \"action\": \"catalog-list\",\n    \"authentication_present\": true,\n    \"device_id\": \"installation-id\",\n    \"request_id\": \"request-uuid\",\n    \"page_size\": 50,\n    \"query_depth\": 1,\n    \"resource_cost\": 10\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate a native API Protection assessment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/api-protection/feedback","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"label\": \"legitimate\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Account Defence","item":[{"name":"Assess a native account-sensitive event","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/account/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"installation-id\",\n    \"event_type\": \"login\",\n    \"outcome\": \"success\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate a native account-risk assessment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/account/feedback","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"label\": \"legitimate\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Retrieve breached-password hash suffixes for native integrations","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/account/password/range","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"prefix\": \"5BAA6\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Trust or revoke a native account device","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/account/trusted-device","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"action\": \"trust\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"installation-id\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Concurrency Control","item":[{"name":"Acquire a native workload concurrency lease","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/concurrency/acquire","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"action\": \"report.generate\",\n    \"method\": \"POST\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"installation-id\",\n    \"route\": \"/api/reports\",\n    \"lease_ttl_seconds\": 120,\n    \"idempotency_key\": \"report-request-9942\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Release a native workload concurrency lease","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/concurrency/release","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"lease_token\": \"vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Renew a native workload concurrency lease","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/concurrency/renew","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"lease_token\": \"vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature\",\n    \"lease_ttl_seconds\": 120\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Dependency Resilience","item":[{"name":"Admit a native downstream dependency call","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/dependency-resilience/admit","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"dependency_key\": \"payments-provider\",\n    \"action\": \"payment.capture\",\n    \"method\": \"POST\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"installation-id\",\n    \"route\": \"/api/payments\",\n    \"is_retry\": false,\n    \"admission_ttl_seconds\": 45\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Report a native admitted dependency outcome","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/dependency-resilience/feedback","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"admission_token\": \"vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature\",\n    \"outcome\": \"success\",\n    \"latency_ms\": 240\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Digital Credentials","item":[{"name":"Issue a native-app holder-bound digital credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/credentials/issue","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Prepare a native-app selective-disclosure presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/credentials/present","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create a native-app credential presentation challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/credentials/presentation/challenge","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a native-app digital credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/credentials/revoke","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a native-app digital credential presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/credentials/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Fraud Defence","item":[{"name":"Assess native email quality risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/fraud/email/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"email\": \"customer@example.com\",\n    \"device_id\": \"installation-id\",\n    \"event_type\": \"signup\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate a native fraud-risk assessment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/fraud/feedback","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"label\": \"legitimate\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Assess native SMS pumping and OTP abuse risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/fraud/sms/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"phone\": \"+2348000000000\",\n    \"device_id\": \"installation-id\",\n    \"event_type\": \"otp_request\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Assess native transaction and commerce fraud risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/fraud/transaction/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"transaction_id\": \"ORDER-9942\",\n    \"device_id\": \"installation-id\",\n    \"event_type\": \"payment\",\n    \"amount\": 125000,\n    \"currency\": \"NGN\",\n    \"high_value\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Ozibus step-up","item":[{"name":"Validate native bound Ozibus step-up evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/step-up/ozibus/evidence/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a native Ozibus-delivered VettiGuard step-up","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/step-up/ozibus/start","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a native Ozibus OTP and issue step-up evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/step-up/ozibus/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Rate Limiting","item":[{"name":"Atomically check and consume native rate-limit capacity","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/rate-limit/check","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"action\": \"payment.create\",\n    \"method\": \"POST\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"installation-id\",\n    \"route\": \"/api/payments\",\n    \"cost\": 1\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Session Integrity","item":[{"name":"Assess native session continuity risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/session/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"session_token\": \"vgsess_replace_me\",\n    \"device_id\": \"installation-id\",\n    \"network_reference\": \"mobile-network-bucket\",\n    \"action\": \"approve-transfer\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a native authenticated session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/session/revoke","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"session_token\": \"vgsess_replace_me\",\n    \"reason\": \"device-sign-out\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a native authenticated session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/session/start","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"installation-id\",\n    \"network_reference\": \"mobile-network-bucket\",\n    \"country_code\": \"NG\",\n    \"action\": \"sign-in\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile Trust Orchestration","item":[{"name":"Annotate a native unified trust decision outcome","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/feedback","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"decision_id\": \"9ecb38c1-fc29-4cb8-bbd5-18272070db4d\",\n    \"label\": \"legitimate\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Produce a native unified trust decision and signed receipt","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/orchestrate","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"action\": \"transfer.submit\",\n    \"subject_id\": \"customer-1842\",\n    \"session_id\": \"session-uuid\",\n    \"transaction_id\": \"transfer-9942\",\n    \"resource_id\": \"beneficiary-204\",\n    \"context\": \"native-transfer\",\n    \"evidence\": [\n        {\n            \"source\": \"device\",\n            \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\"\n        },\n        {\n            \"source\": \"stepup\",\n            \"evidence\": \"vgstep.payload.signature\"\n        },\n        {\n            \"source\": \"graph\",\n            \"device_id\": \"native-installation\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a native trust receipt","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/receipt/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"receipt\": \"vgtr.payload.signature\",\n    \"action\": \"transfer.submit\",\n    \"subject_id\": \"customer-1842\",\n    \"resource_id\": \"beneficiary-204\",\n    \"context\": \"native-transfer\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile device authorization","item":[{"name":"Register a device-bound public credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/device-credentials/register","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"credential_label\": \"Primary phone\",\n    \"public_key\": \"base64url-public-key\",\n    \"installation_id\": \"opaque-installation-id\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a device-bound credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/device-credentials/revoke","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"credential_key\": \"vg_device_replace_me\",\n    \"reason\": \"device-replaced\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Complete device-bound authorization","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/device/authorization/complete","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"authorization_token\": \"vg_authorization_replace_me\",\n    \"credential_key\": \"vg_device_replace_me\",\n    \"signature\": \"base64url-signature\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create a device authorization intent","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/device/authorization/intent","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"approve-transfer\",\n    \"operation_reference\": \"TRANSFER-12345\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a device authorization proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/device/authorization/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"response\": \"vg_device_response_replace_me\",\n    \"action\": \"approve-transfer\",\n    \"operation_reference\": \"TRANSFER-12345\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile device intelligence","item":[{"name":"Assess native device assurance and risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/device/assess","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile facial authorization","item":[{"name":"Post mobile facial authorization complete","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/authorization/complete","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial authorization intent","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/authorization/intent","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial authorization session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/authorization/session","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial authorization siteverify","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/authorization/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile facial enrollment","item":[{"name":"Post mobile facial enrollment complete","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/enrollment/complete","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial enrollment intent","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/enrollment/intent","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial enrollment revoke","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/enrollment/revoke","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial enrollment session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/enrollment/session","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial enrollment siteverify","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/enrollment/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial enrollment status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/enrollment/status","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile facial liveness","item":[{"name":"Post mobile facial complete","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/complete","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial decision","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/decision","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/session","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial session cancel","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/session/cancel","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial session status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/session/status","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post mobile facial siteverify","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/facial/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile reusable identity","item":[{"name":"Create a native selective reusable identity presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/identity/reusable/present","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a native reusable identity presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/identity/reusable/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile transaction authorization","item":[{"name":"Issue a native one-use transaction authorization proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/transactions/authorize","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a native transaction authorization proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/transactions/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"[]","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile trust decisions","item":[{"name":"Select a native trust method","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/decision","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"approve-transfer\",\n    \"subject_id\": \"customer-4821\",\n    \"requested_assurance\": \"device-bound\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.419999999999999984456877655247808434069156646728515625,\n    \"failed_attempts_5m\": 2,\n    \"new_device\": true,\n    \"anonymous_network\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a native trust proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"approve-transfer\",\n    \"subject_id\": \"customer-4821\",\n    \"requested_assurance\": \"device-bound\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.419999999999999984456877655247808434069156646728515625,\n    \"failed_attempts_5m\": 2,\n    \"new_device\": true,\n    \"anonymous_network\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile trust graph","item":[{"name":"Post mobile trust graph intelligence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/graph/intelligence","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"native-installation\",\n    \"network_id\": \"mobile-network-bucket\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Record native privacy-preserving trust graph observations","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/graph/observe","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"approve-transfer\",\n    \"subject_id\": \"customer-4821\",\n    \"requested_assurance\": \"device-bound\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.419999999999999984456877655247808434069156646728515625,\n    \"failed_attempts_5m\": 2,\n    \"new_device\": true,\n    \"anonymous_network\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read native one-hop trust graph risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust/graph/risk","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"action\": \"approve-transfer\",\n    \"subject_id\": \"customer-4821\",\n    \"requested_assurance\": \"device-bound\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.419999999999999984456877655247808434069156646728515625,\n    \"failed_attempts_5m\": 2,\n    \"new_device\": true,\n    \"anonymous_network\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Mobile trust journeys","item":[{"name":"Escalate a native journey to assisted review","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/journeys/escalate","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"journey_key\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"recover-account\",\n    \"platform\": \"ios\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.5500000000000000444089209850062616169452667236328125,\n    \"new_device\": true,\n    \"unusual_time\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a native Trust Journey step","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/journeys/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"journey_key\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"recover-account\",\n    \"platform\": \"ios\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.5500000000000000444089209850062616169452667236328125,\n    \"new_device\": true,\n    \"unusual_time\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a native Trust Journey","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/journeys/start","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"journey_key\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"recover-account\",\n    \"platform\": \"ios\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.5500000000000000444089209850062616169452667236328125,\n    \"new_device\": true,\n    \"unusual_time\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read native Trust Journey status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/journeys/status","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"journey_key\": \"account-recovery\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"recover-account\",\n    \"platform\": \"ios\",\n    \"app_id\": \"com.example.app\",\n    \"risk_score\": 0.5500000000000000444089209850062616169452667236328125,\n    \"new_device\": true,\n    \"unusual_time\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Native Mobile Trust Credentials","item":[{"name":"Verify the native mobile key signature and issue one-use evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/mobile/trust-credentials/authentication/complete","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"app_key\": \"vg_mobile_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"installation_id\": \"opaque-installation-id\",\n    \"challenge_token\": \"opaque-one-use-token\",\n    \"signature\": \"base64url-es256-signature\",\n    \"signature_counter\": 13\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create an action-bound native mobile possession challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust-credentials/authentication/options","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"installation_id\": \"opaque-installation-id\",\n    \"credential_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"action\": \"payment.approve\",\n    \"context\": \"ORDER-9942\",\n    \"signature_counter\": 12\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and optionally consume native mobile authentication evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust-credentials/evidence/verify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"evidence\": \"vgmk.payload.signature\",\n    \"action\": \"payment.approve\",\n    \"subject_id\": \"customer-1842\",\n    \"context\": \"ORDER-9942\",\n    \"consume\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Complete native mobile key registration with proof of possession","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/mobile/trust-credentials/registration/complete","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"app_key\": \"vg_mobile_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"installation_id\": \"opaque-installation-id\",\n    \"challenge_token\": \"opaque-one-use-token\",\n    \"signature\": \"base64url-es256-signature\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start integrity-bound native mobile key registration","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust-credentials/registration/options","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"subject_id\": \"customer-1842\",\n    \"installation_id\": \"opaque-installation-id\",\n    \"public_jwk\": {\n        \"kty\": \"EC\",\n        \"crv\": \"P-256\",\n        \"x\": \"base64url-x\",\n        \"y\": \"base64url-y\"\n    },\n    \"label\": \"Primary phone\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a native mobile trust credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/trust-credentials/revoke","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"credential_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"reason\": \"device-replaced\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Native mobile verification","item":[{"name":"Register or validate an App Attest key","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/attest","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"app_key\": \"vg_mobile_replace_me\",\n    \"platform\": \"ios\",\n    \"app_id\": \"com.example.app\",\n    \"nonce_token\": \"signed-nonce\",\n    \"attestation\": \"base64-attestation\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Issue a native verification challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/challenge","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"app_key\": \"vg_mobile_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"nonce_token\": \"signed-nonce\",\n    \"integrity_token\": \"provider-token\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Annotate a native detection assessment outcome","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/detection/feedback","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"assessment_id\": \"4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24\",\n    \"label\": \"legitimate\",\n    \"reason_code\": \"customer-confirmed\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Issue a signed mobile request nonce","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/nonce","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"app_key\": \"vg_mobile_replace_me\",\n    \"platform\": \"android\",\n    \"app_id\": \"com.example.app\",\n    \"action\": \"sign-in\",\n    \"installation_id\": \"opaque-installation-id\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a native challenge token","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/siteverify","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_mobile_secret_replace_me\",\n    \"response\": \"single-use-mobile-token\",\n    \"action\": \"sign-in\",\n    \"expected_platform\": \"android\",\n    \"expected_app_id\": \"com.example.app\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Solve a native verification challenge","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Authorization","value":"Bearer {{mobile_credential}}","type":"text"}],"url":"{{base_url}}/mobile/solve","description":"Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.","body":{"mode":"raw","raw":"{\n    \"app_key\": \"vg_mobile_replace_me\",\n    \"challenge_id\": \"4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24\",\n    \"answer\": true,\n    \"action\": \"sign-in\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Ozibus integration","item":[{"name":"Post integrations ozibus events","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"},{"key":"Stripe-Signature","value":"{{stripe_signature}}","type":"text"}],"url":"{{base_url}}/integrations/ozibus/events","description":"ozibus_hmac","body":{"mode":"raw","raw":"{\n    \"workspace_id\": 1,\n    \"event_id\": \"ozb-event-2048\",\n    \"channel\": \"sms\",\n    \"event_type\": \"delivered\",\n    \"assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"provider_status\": \"delivered\",\n    \"delivery_latency_ms\": 920\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Post integrations ozibus preflight","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/integrations/ozibus/preflight","description":"ozibus_hmac","body":{"mode":"raw","raw":"{\n    \"workspace_id\": 1,\n    \"channel\": \"sms\",\n    \"event_type\": \"otp_request\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"phone\": \"+2348000000000\",\n    \"high_cost_destination\": false\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Ozibus step-up","item":[{"name":"Validate bound VettiGuard Ozibus step-up evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/step-up/ozibus/evidence/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"evidence\": \"vgstep.payload.signature\",\n    \"action\": \"account.recovery\",\n    \"subject_id\": \"customer-1842\",\n    \"context\": \"recovery-9942\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start an Ozibus-delivered VettiGuard step-up","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/step-up/ozibus/start","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"account.recovery\",\n    \"subject_id\": \"customer-1842\",\n    \"email\": \"customer@example.com\",\n    \"context\": \"recovery-9942\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify an Ozibus OTP and issue bound step-up evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/step-up/ozibus/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"stepup_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"otp\": \"123456\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Passkeys as a Service","item":[{"name":"Verify a passkey assertion and issue one-use authentication evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/passkeys/authentication/complete","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"challenge_token\": \"opaque-challenge-token\",\n    \"credential\": {\n        \"id\": \"base64url-credential-id\",\n        \"rawId\": \"base64url-credential-id\",\n        \"type\": \"public-key\",\n        \"response\": {\n            \"clientDataJSON\": \"base64url-client-data\",\n            \"authenticatorData\": \"base64url-authenticator-data\",\n            \"signature\": \"base64url-signature\",\n            \"userHandle\": \"base64url-user-handle\"\n        }\n    }\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create passkey authentication options, including discoverable sign-in","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/passkeys/authentication/options","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"origin\": \"https://app.example.com\",\n    \"action\": \"sign-in\",\n    \"context\": \"login-9942\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke a protected-site passkey credential","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/passkeys/credentials/revoke","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"credential_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\",\n    \"reason\": \"customer-request\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and optionally consume VettiGuard passkey authentication evidence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/passkeys/evidence/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"evidence\": \"vgpk.payload.signature\",\n    \"action\": \"sign-in\",\n    \"subject_id\": \"customer-1842\",\n    \"context\": \"login-9942\",\n    \"consume\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and store a protected-site passkey registration","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/passkeys/registration/complete","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"challenge_token\": \"opaque-challenge-token\",\n    \"credential\": {\n        \"id\": \"base64url-credential-id\",\n        \"rawId\": \"base64url-credential-id\",\n        \"type\": \"public-key\",\n        \"response\": {\n            \"clientDataJSON\": \"base64url-client-data\",\n            \"attestationObject\": \"base64url-attestation\",\n            \"transports\": [\n                \"internal\",\n                \"hybrid\"\n            ]\n        }\n    },\n    \"label\": \"Primary passkey\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Create WebAuthn passkey registration options for an opaque subject","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/passkeys/registration/options","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"origin\": \"https://app.example.com\",\n    \"display_name\": \"Customer account\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Platform","item":[{"name":"Inspect API availability and canonical links","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Read the machine-readable API changelog","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/changelog.json","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Check API health without infrastructure disclosure","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/health","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Download the OpenAPI 3.1 contract","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/openapi.json","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]},{"name":"Download the Postman collection","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{base_url}}/postman-collection.json","description":"Public metadata endpoint that does not reveal private infrastructure details."},"response":[]}]},{"name":"Rate Limiting","item":[{"name":"Atomically check and consume rate-limit capacity","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/rate-limit/check","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"payment.create\",\n    \"method\": \"POST\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"route\": \"/api/payments\",\n    \"cost\": 1,\n    \"api_protection_assessment_id\": \"70f05cc7-989e-41f0-9a37-c9884d323a67\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Reusable identity","item":[{"name":"Create a selective reusable identity presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/identity/reusable/present","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"holder_token\": \"vgid_replace_me\",\n    \"claims\": [\n        \"identity_verified\",\n        \"assurance_level\",\n        \"age_over_18\"\n    ]\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a reusable identity presentation","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/identity/reusable/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"presentation\": \"vgidp.payload.signature\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Session Integrity","item":[{"name":"Assess authenticated-session continuity risk","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/session/assess","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"session_token\": \"vgsess_replace_me\",\n    \"device_id\": \"browser-device\",\n    \"network_reference\": \"network-bucket-19\",\n    \"country_code\": \"NG\",\n    \"action\": \"checkout-confirm\",\n    \"authentication_age_seconds\": 900\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Revoke an authenticated session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/session/revoke","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"session_token\": \"vgsess_replace_me\",\n    \"reason\": \"customer-sign-out\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a continuously assessed authenticated session","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/session/start","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"network_reference\": \"network-bucket-19\",\n    \"country_code\": \"NG\",\n    \"action\": \"sign-in\",\n    \"trust_level\": \"standard\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Transaction authorization","item":[{"name":"Issue a one-use proof for an exact transaction intent","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/transactions/authorize","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"payment.capture\",\n    \"subject_id\": \"customer-1842\",\n    \"resource_id\": \"ORDER-9942\",\n    \"decision_receipt\": \"vgtr.payload.signature\",\n    \"intent\": {\n        \"transaction_id\": \"PAY-9942\",\n        \"amount\": \"125000.00\",\n        \"currency\": \"NGN\",\n        \"payee_id\": \"merchant-88\"\n    }\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a transaction authorization proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/transactions/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"payment.capture\",\n    \"proof\": \"vgtx.payload.signature\",\n    \"intent\": {\n        \"transaction_id\": \"PAY-9942\",\n        \"amount\": \"125000.00\",\n        \"currency\": \"NGN\",\n        \"payee_id\": \"merchant-88\"\n    }\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Trust Orchestration","item":[{"name":"Annotate a unified trust decision outcome","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/feedback","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"decision_id\": \"9ecb38c1-fc29-4cb8-bbd5-18272070db4d\",\n    \"label\": \"legitimate\",\n    \"reason_code\": \"order-completed\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Produce a unified trust decision and signed receipt","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/orchestrate","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"checkout.submit\",\n    \"subject_id\": \"customer-1842\",\n    \"session_id\": \"session-uuid\",\n    \"transaction_id\": \"order-9942\",\n    \"resource_id\": \"cart-9942\",\n    \"context\": \"production-checkout\",\n    \"evidence\": [\n        {\n            \"source\": \"device\",\n            \"assessment_id\": \"4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24\"\n        },\n        {\n            \"source\": \"passkey\",\n            \"evidence\": \"vgpk.payload.signature\"\n        },\n        {\n            \"source\": \"graph\",\n            \"device_id\": \"browser-device\"\n        }\n    ]\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a context-bound trust receipt","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/receipt/verify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"receipt\": \"vgtr.payload.signature\",\n    \"action\": \"checkout.submit\",\n    \"subject_id\": \"customer-1842\",\n    \"resource_id\": \"cart-9942\",\n    \"context\": \"production-checkout\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Trust decisions","item":[{"name":"Select the required assurance method","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/decision","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"action\": \"approve-transfer\",\n    \"subject_id\": \"customer-4821\",\n    \"requested_assurance\": \"standard\",\n    \"risk_score\": 0.419999999999999984456877655247808434069156646728515625,\n    \"request_velocity_5m\": 12,\n    \"failed_attempts_5m\": 2,\n    \"transaction_amount\": 250000,\n    \"new_device\": true,\n    \"anonymous_network\": false,\n    \"country_code\": \"NG\",\n    \"network_type\": \"mobile\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify and consume a normalised trust proof","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/siteverify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"response\": \"single-use-response-token\",\n    \"action\": \"approve-transfer\",\n    \"expected_assurance\": \"high\",\n    \"require_identity\": true,\n    \"require_liveness\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Trust graph","item":[{"name":"Inspect explainable graph velocity, cluster, and bounded multi-hop intelligence","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/graph/intelligence","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\",\n    \"network_id\": \"network-bucket\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Record privacy-preserving trust graph observations","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/graph/observe","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"nodes\": [\n        {\n            \"type\": \"subject\",\n            \"value\": \"customer-1842\",\n            \"risk_score\": 0.08000000000000000166533453693773481063544750213623046875\n        },\n        {\n            \"type\": \"device\",\n            \"value\": \"browser-device\",\n            \"risk_score\": 0.1499999999999999944488848768742172978818416595458984375\n        }\n    ],\n    \"edges\": [\n        {\n            \"from\": 0,\n            \"to\": 1,\n            \"type\": \"used\",\n            \"strength\": 0.90000000000000002220446049250313080847263336181640625\n        }\n    ]\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read trust graph risk with optional qualified advanced enrichment","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/trust/graph/risk","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"subject_id\": \"customer-1842\",\n    \"device_id\": \"browser-device\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]},{"name":"Trust journeys","item":[{"name":"Escalate a journey to assisted review","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/journeys/escalate","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"session_token\": \"vg_journey_replace_me\",\n    \"reason_code\": \"accessibility-alternative-required\",\n    \"priority\": \"normal\"\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Verify a Trust Journey step","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/journeys/siteverify","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"session_token\": \"vg_journey_replace_me\",\n    \"response\": \"vg_response_replace_me\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"approve-transfer\",\n    \"consent_accepted\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Start a published Trust Journey","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/journeys/start","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"journey_key\": \"transaction-approval\",\n    \"subject_id\": \"customer-4821\",\n    \"action\": \"approve-transfer\",\n    \"operation_reference\": \"TRANSFER-12345\",\n    \"risk_score\": 0.419999999999999984456877655247808434069156646728515625,\n    \"request_velocity_5m\": 12,\n    \"transaction_amount\": 250000,\n    \"new_device\": true\n}","options":{"raw":{"language":"json"}}}},"response":[]},{"name":"Read Trust Journey session status","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{base_url}}/journeys/status","description":"Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.","body":{"mode":"raw","raw":"{\n    \"secret\": \"vg_secret_replace_me\",\n    \"session_token\": \"vg_journey_replace_me\"\n}","options":{"raw":{"language":"json"}}}},"response":[]}]}]}